WindowsEventLogDataSource Class
Definition of which Windows Event Log events will be collected and how they will be collected. Only collected from Windows machines.
Constructor
WindowsEventLogDataSource(*, streams: List[str | _models.KnownWindowsEventLogDataSourceStreams] | None = None, x_path_queries: List[str] | None = None, transform_kql: str | None = None, name: str | None = None, **kwargs: Any)
Keyword-Only Parameters
| Name | Description |
|---|---|
|
streams
|
List of streams that this data source will be sent to. A stream indicates what schema will be used for this data and usually what table in Log Analytics the data will be sent to. Default value: None
|
|
x_path_queries
|
A list of Windows Event Log queries in XPATH format. Default value: None
|
|
transform_kql
|
The KQL query to transform the data source. Default value: None
|
|
name
|
A friendly name for the data source. This name should be unique across all data sources (regardless of type) within the data collection rule. Default value: None
|
Variables
| Name | Description |
|---|---|
|
streams
|
List of streams that this data source will be sent to. A stream indicates what schema will be used for this data and usually what table in Log Analytics the data will be sent to. |
|
x_path_queries
|
A list of Windows Event Log queries in XPATH format. |
|
transform_kql
|
The KQL query to transform the data source. |
|
name
|
A friendly name for the data source. This name should be unique across all data sources (regardless of type) within the data collection rule. |